Anonymous
2026-09-07 20:35:13
(4 hours ago)
Bot / seems abusive / Apache connections: 34
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇦🇹
penguin-solutions.at
2026-09-07 20:11:15
(4 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇩🇪
ghostwarriors
2026-09-07 19:50:06
(4 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-07 19:44:33
(4 hours ago)
35.252.198.48 - - [07/Sep/2026:21:44:29 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env ...
show more
35.252.198.48 - - [07/Sep/2026:21:44:29 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 404 767 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0) Chrome/126.0.3769.115 Safari/537.36"
35.252.198.48 - - [07/Sep/2026:21:44:29 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 767 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.2; +https://openai.com/gptbot) Chrome/131.0.4733.230 Safari/537.36"
35.252.198.48 - - [07/Sep/2026:21:44:29 +0200] "GET /@fs/.env.development?raw?? HTTP/1.1" 404 767 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php) Chrome/124.0.5857.154 Safari/537.36"
35.252.198.48 - - [07/Sep/2026:21:44:29 +0200] "GET /@fs/.env.production?raw?? HTTP/1.1" 404 767 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X
show less
Bad Web Bot
🇳🇱
e.fierstra
2026-09-07 18:48:01
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 18:25:02
(6 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:13:35
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.198.48 (48.198.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.198.48 (48.198.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:13:28.919535 2026] [security2:error] [pid 872275:tid 872304] [client 35.252.198.48:47146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cocoonprojects.com"] [uri "/@fs/root/.env"] [unique_id "ap7-yLZBiXUuFNMTNeEpvAAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-07 17:51:25
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.252.198.48 (US/United States/48.198. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.252.198.48 (US/United States/48.198.252.35.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-07 17:35:13
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.198.48 (48.198.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.198.48 (48.198.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:35:06.989418 2026] [security2:error] [pid 23852:tid 23852] [client 35.252.198.48:30366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caonabo.com"] [uri "/@fs/root/.env"] [unique_id "ap71yj2_S--B19s6zHTgFgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 17:32:08
(7 hours ago)
Excessive 404/403 errors
Brute-Force
🇨🇭
backslash
2026-09-07 17:27:00
(7 hours ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 17:18:56
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.198.48 (48.198.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.198.48 (48.198.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:18:52.030395 2026] [security2:error] [pid 19904:tid 19904] [client 35.252.198.48:55622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jillbauman.com"] [uri "/@fs/app/.env"] [unique_id "ap7x_BEHWuGtFMJH53R_0AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-07 17:18:28
(7 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-07 17:13:32
(7 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇨🇦
SoteriaCovenant
2026-09-07 16:58:58
(7 hours ago)
Automated probe: /config.php.bak on Soteria Global infrastructure. No vulnerable software present.
Hacking